Of course this is just an issue of how Checkpoint has implemented the proxy arp to help users and adminsitrators to automatically do the necessary configuration to support the NAT.  This is not necessary (just like it has always been) in the case where you have already configured routing to send the packets to the appropriate interface of the firewall without proxy arping.  This can be done by configuring static host and/or networks route on the next hop router.

